Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
2020-09-23T14:15:13.413
2024-11-21T05:25:12.047
Modified
CVSSv3.1: 7.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | liquibase_runner | ≤ 1.4.5 | Yes |